Skip to main content

LockBit appears hacked, exposing part of its internal conversations

The LockBit ransomware group apparently suffered a breach in its own infrastructure.

CybersecuritySeintec Team2-3 min read
LockBit appears hacked, exposing part of its internal conversations

News summary

The LockBit ransomware group apparently suffered a breach in its own infrastructure. One of its dark web pages was replaced by a message and a link to data that, according to researchers, appeared to include conversations with victims.

The downfall of a criminal group does not eliminate the risk. The ecosystem evolves and substitutes emerge; corporate defence must focus on resilience, backups and recovery capabilities.

Source: Reuters — 8 May 2025

What happened

In May 2025 the LockBit ransomware group appeared to suffer a breach of its own infrastructure. One of its dark web pages was replaced with a message and a link to a data set that, according to security analysts, appeared to include internal conversations and communications with victims.

The incident was not claimed by authorities nor officially attributed to a law enforcement operation; it was interpreted as a possible action by another actor or a dispute within the criminal ecosystem itself.

What it means for a mid-sized business

The breach or hacking of one specific ransomware group does not eliminate ransomware risk in general. The criminal ecosystem is fragmented and changes quickly: when one group loses infrastructure or reputation, others are ready to take its place.

For a business, the news should not be read as a sign that risk has fallen, but as a reminder that its own defences (recoverable backups, segmentation, response plans) are the only thing it directly controls.

What to review

Resilience elements against ransomware, independent of which group is attacking:

  • Recoverable backups, disconnected from the main environment and tested periodically.
  • A ransomware incident response plan with roles and decisions defined in advance.
  • Network segmentation that limits spread between devices and servers.
  • A clear policy on ransom payment, decided before an incident occurs, not during one.

Frequently Asked Questions

Who hacked LockBit?
It was not officially attributed to a specific actor; analysts suggested a possible action by another group or an internal dispute, without definitive confirmation.
Does this mean LockBit has disappeared?
Not necessarily. Ransomware groups have suffered similar setbacks in the past and reappeared with new infrastructure or a new brand.
Does this change my company's exposure to ransomware?
Not directly. Risk depends on your own defences, not on the situation of one specific criminal group.

Concepts mentioned in this article: Backup · Ransomware

If you wish to strengthen the security, continuity and performance of your infrastructure, Seintec can support you from diagnosis through to implementation. Contact us to speak with a specialist.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.